US11575512B2

Configurable network security for networked energy resources, and associated systems and methods

Summary by NHIP

ICN Trust Rule Enforcement

The method secures access to networked electrical power generation resources by maintaining trust rules containing origin, target, and action identifiers. An enforcement system cryptographically verifies certificates and determines authorization based on subscribed Information Centric Networking messages matching these identifiers.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Secure communication between users and resources of an electrical infrastructure and associated systems and methods. A representative secure distributed energy resource (DER) communication system provides for the creation of trust rules that govern the permitted communications between users and resources of an electrical infrastructure system, and the enforcement of the trust rules.

US11575512B2, drawing sheet 1
Sheet 1 of 13

Term

14.9 yearsleft in the term

Expires 2 August 2041, including 3 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

17 claims: 1 independent, 16 dependent

  1. 1
    Broadest claimClaim Score 23, narrow(NHIP)A method, performed by a computing system, to secure access to networked electrical power generation load control and storage resources, the method comprising:maintaining, at a computing system, a trust policy comprised of a plurality of trust rules, wherein each trust rule comprises an origin identifier, a target identifier, and an action identifier;generating a first Information Centric Networking (ICN) message based on a trust rule selected from the plurality of trust rules, wherein the target identifier of the selected trust rule corresponds to a networked electrical power generation load control and storage resource (NEPGLSR);publishing, on a communication channel, the first ICN message, wherein the publication of the first ICN message causes an enforcement computing system, on the communication channel and associated with a first entity, to maintain authorization information characterized by the origin identifier, target identifier, and action identifier of the selected trust rule;cryptographically signing a certificate associated with a second entity, wherein the second entity corresponds to the origin identifier of the selected trust rule, and wherein the certificate includes a second entity name defined in an ICN hierarchical namespace and a second entity public key;and wherein the enforcement computing system, in response to subscribing to a second ICN message, the second ICN message including the second entity name defined in the ICN hierarchical namespace: determines, from the second ICN message, a target identifier and an action identifier of the second ICN message, wherein the target identifier of the second ICN message corresponds to the NEPGLSR;and determines whether the second entity, associated with the second entity name, is authorized to perform an action, corresponding to the action identifier of the second ICN message, on the NEPGLSR, based on the maintained authorization information.